VulnerabilityAnalyzed
CVE-2025-5543
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108.
MEDIUM 4.8EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- totolink/x2000r firmware
- Source
- cna@vuldb.com
References
- https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/X2000R/XSS_parent_controlExploit
- https://vuldb.com/?ctiid.310993Permissions Required, Vendor Advisory
- https://vuldb.com/?id.310993Third Party Advisory, Vendor Advisory
- https://vuldb.com/?submit.585728Third Party Advisory, Vendor Advisory
- https://www.totolink.net/Product
- https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/X2000R/XSS_parent_controlExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.